Security Alert: Check Point SmartConsole Flaw Under Active Exploitation (CVE-2026-16232)
Check Point has released security updates to address three security vulnerabilities, including the critical zero-day CVE-2026-16232 affecting the SmartConsole login process, which has been actively exploited and could allow unauthenticated attackers to gain full administrative access to vulnerable Security Management Server and Multi-Domain Security Management Server (MDS) environments. The update also addresses CVE-2026-62144 and CVE-2026-62145 affecting other Check Point management and security products.
Affected Systems:
Check Point Security Management Server and Multi-Domain Security Management Server (MDS): Versions R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10.
Security Risks
Successful exploitation could allow attackers to bypass SmartConsole authentication, gain full administrative access, and modify security policies and configurations on vulnerable management servers.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
Apply the latest supported security updates for affected Check Point products as soon as possible to address the vulnerability.
Upgrade to the following supported versions:
Check Point Security Management Server and Multi-Domain Security Management Server (MDS) versions:
R81.20: Jumbo HotFix Accumulator Take 158 or newer releases
R82: Jumbo HotFix Accumulator Take 118 or newer releases
R82.10: Jumbo HotFix Accumulator Take 36 or newer releases
For additional mitigation guidance, follow the recommended Gateway and Management security hardening practices outlined in Check Point’s Hardening Guide.
Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.